STIGQter STIGQter: STIG Summary: IBM AIX 7.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

AIX kernel core dumps must be disabled unless needed.

DISA Rule

SV-215397r508663_rule

Vulnerability Number

V-215397

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

AIX7-00-003094

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable kernel core dumps on the system by setting primary and secondary dump devices to "sysdumpnull" by running following commands:
# sysdumpdev -P -p /dev/sysdumpnull
# sysdumpdev -P -s /dev/sysdumpnull

Check Contents

Determine if kernel core dumps are enabled on the system using command:

# sysdumpdev -l
primary /dev/sysdumpnull
secondary /dev/sysdumpnull

Look at both the primary and secondary dump devices.

If either the primary or secondary dump device is not "/dev/sysdumpnull", this is a finding.

Vulnerability Number

V-215397

Documentable

False

Rule Version

AIX7-00-003094

Severity Override Guidance

Determine if kernel core dumps are enabled on the system using command:

# sysdumpdev -l
primary /dev/sysdumpnull
secondary /dev/sysdumpnull

Look at both the primary and secondary dump devices.

If either the primary or secondary dump device is not "/dev/sysdumpnull", this is a finding.

Check Content Reference

M

Target Key

4012

Comments